Impact
IBM OpenBMC firmware revisions FW1060.00 through FW1060.80 contain a flaw in the firmware update process that allows an attacker who has authenticated administrator‑level access to a Baseboard Management Controller to execute arbitrary code. The flaw is classified as a CWE‑22 type vulnerability involving improper handling of control data during the update sequence and can compromise confidentiality, integrity and availability.
Affected Systems
The affected products are IBM OpenBMC firmware images FW1060.00 to FW1060.80. The flaw applies to IBM Power System models: Power System S1022 (9105‑22A), S1024 (9105‑42A), S1022s (9105‑22B), S1014 (9105‑41B), L1022 (9786‑22H), L1024 (9786‑42H), E1050 (9043‑MRX), and S1012 (9028‑21B).
Risk and Exploitability
The CVSS base score of 6.8 indicates medium severity. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires authenticated administrator access to the BMC and occurs during the firmware update process, so the threat is limited to environments where the BMC interface is reachable by an authenticated user.
OpenCVE Enrichment